Clean the cache that's created on the clients containing the groups for a user is a first try. If you log on to a machine with a user that you've never logged on with on this specific machine, is it still broken?